The $130M Bug That Was Hiding in Plain Sight

Bitcoin near $65K, ETF flows turn positive, CLARITY Act hits its final week

Good morning. This is Maestro's Market Insights, where we track the forces shaping Bitcoin and digital capital markets.

Today: institutional Bitcoin capital is diverging, a major hardware wallet flaw is reshaping the conversation around self-custody, and the Bitcoin network is showing one of the rarest mining signals in its history.

P.S. We also launched a new home for Mezzamine. Explore our Bitcoin-native credit markets for miners and lenders at https://www.mezzamine.com/.

Market Prices

Markets: Bitcoin is holding just under $65,000, resistance at $66,000, support near $63,000. Spot ETFs pulled in $626M over three days, the best stretch since May, even as Strategy sold 1,638 BTC to fund buybacks instead of buying more. Mining difficulty sits 14% below January's high, pushing miners like Hut 8 further into AI infrastructure.

Market Updates

CLARITY Act Down to the Wire

Crypto market structure legislation is entering its final window before Congress recesses.

Coldcard Hack Grows Past $130M

A 2021 firmware flaw let attackers computationally reconstruct "unguessable" seed phrases, and losses have nearly doubled since disclosure.

Capital Flows Split Again

ETFs snapped back hard this week just as the largest corporate Bitcoin holder pulled back.

Why It Matters

Regulatory clarity, security trust, and institutional behavior are all live right now. A handful of Senate votes could decide market-structure rules for years. One old line of code just cost wallet holders $130M, proof that "cold storage" still depends on trusting a vendor. And institutional demand is split down the middle: ETFs are buying, the biggest corporate holder isn't.

By The Numbers

$626M
US spot Bitcoin ETFs pulled in $626M over the first three trading days of the week, the strongest stretch since early May and a sharp reversal from last week's $33.8M low.

-14%
Bitcoin's mining difficulty sits at 126.23T, 14% below January's peak and 19% below November 2025's all-time high of 155.97T.

$130M+
Losses from the Coldcard hardware wallet hack passed $130M this week as more victims came forward, after a single 2021 firmware flaw exposed predictable seed-phrase generation.

The Deep Dive

The Coldcard Hack Broke More Than Wallets

The Signal

No phishing. No malware. No device ever touched. A single build flag from 2021 sat in production for five years, then let attackers computationally reconstruct "random" seed phrases in 41 minutes. It's being called the worst self-custody failure in Bitcoin's history. That's forcing a question institutional lenders and custodians can't dodge: does holding your own keys actually mean you control your own risk?

The Numbers

Metric

Value

BTC drained, first wave

1,082.65 BTC (~$70M)

Wallets drained

1,196

Attack window, wave one

41 min, July 30, 01:10–01:51 UTC

Total losses as of Aug 4

$130M+, four attack waves

Root cause

2021 build flag; RNG check verified flag existed, not its value

Effective key space post-flaw

~4 billion combos, brute-forceable

Known attacker groups

12+, exploiting independently

Fixed firmware released

July 31, 9:33am ET; MK3, MK4, MK5, Q patched

AI code review, pre-disclosure

Tested against frontier models; none caught it

All crypto hacks, H1 2026

$972M across 207 incidents (down from $2.3B H1 2025)

What Changed

  • The flaw: an internal build flag skipped Coldcard's dedicated hardware RNG. A supporting library checked only that the flag existed, not what it was set to, so key generation fell back to predictable inputs (chip serial number, clock registers).

  • Coinkite initially said only Mk3 was at risk. Independent researchers at Block disputed that, and Coinkite ultimately shipped fixed firmware for MK4, MK5, and Q too. The scope grew after disclosure, not before it.

  • At least a dozen separate groups exploited the bug independently across four waves, a sign the flaw was easy to rediscover once anyone suspected it.

  • Coinkite ran the vulnerable code through multiple frontier AI models before the hack. None flagged it: the bug lived at a build/sub-module boundary, not the cryptographic logic AI review tools are tuned to check.

  • Other major hardware wallets (Ledger, Trezor, Foundation) use different entropy designs: certified secure elements, multiple independent entropy sources, open-source reproducible builds. Researchers see this as an isolated implementation failure, not an industry-wide one.

The Read

Self-custody didn't fail here. One vendor's code did, and that distinction is the whole story. Institutional custody is repositioning around it: the product is no longer "we hold your keys," it's multi-party approval, independent key generation across separate vendors, audit trails, and insurance, because "did you buy a well-reviewed hardware wallet" stopped being sufficient due diligence. The AI angle cuts both ways too: it missed this bug before disclosure, but per Coldcard's NVK, hackers are now running the same tools against every other wallet on the market.

Watch Next

  • Whether Block's claim of broader Mk4/Q/Mk5 exposure gets independently confirmed at scale, against Coinkite's narrower initial framing.

  • Early legal theories (breach of warranty, negligence, consumer protection) against Coinkite moving through courts. No findings yet, but the framework is already being built.

  • Whether AI-assisted vulnerability hunting turns up a flaw in a second hardware wallet before the next disclosure cycle.

  • Quantum resistance is the long-dated version of this same risk: a vendor-level cryptographic assumption quietly failing years after devices ship. Not an active threat this week, but the same category of blind spot.

Maestro Updates

New Mezzamine Experience Live

The new Mezzamine experience is live, a clearer look at Bitcoin-native credit markets built for miners and lenders.

How Maestro Built Its New Site With AI

Maestro's new site was designed and shipped end-to-end by one person and AI agents, no design or frontend team, from HTML prototypes to subagent-driven development.

Book a Call: Here

Contact Us: [email protected]